Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Community Member

AnyConnect double certificate authentication

Hallo,

can i implement a double certificate authentication on the Cisco ASA?

First Auth:

Machine certificate

Second Auth:

User certificate + RADIUS(OTP)

or:

First Auth:

User certificate + RADIUS(OTP)

Second Auth:

Machine certificate

mfg

Michael

Everyone's tags (1)
1 REPLY
Hall of Fame Super Silver

AnyConnect double certificate authentication

You should be able to use a Dynamic Access Policy (DAP) setup to first check for the machine certificate. Then further configure the profile to check for user certificate plus the RADIUS OTP authentication.

I believe it will require Anyconnect Premium license to use DAP.

237
Views
0
Helpful
1
Replies
CreatePlease to create content